Campaign-specific starting point
Emergency policy for Laravel Lang package compromise
This is a conservative starting point selected from the reviewed public recipe registry based on the campaign’s first reviewed artifact class. It is not automatically applied.
Selected recipe
Block known-malicious package installs
Block supported install actions for packages already classified as malicious.
Matcher: package = malicious-package. Decision: block.
Review the actual artifact identifiers, affected environment, coverage, and campaign evidence before rollout. The recipe does not claim Guard covers every stage of the campaign.
Campaign sources
- Socket: Laravel Lang compromise
- HOL Guard 2.0.1112: Composer support matrix
- PyPI: HOL Guard stable release metadata at 2026-08-21
- HOL Guard v2.2.5: Composer support matrix
- HOL Guard v2.2.122: stable-line project metadata
- HOL Guard v2.2.122: Composer support matrix
- HOL Guard v3.0.0: stable project metadata
- HOL Guard v3.0.0: Composer support matrix
- HOL Guard v3.0.18: official release
- HOL Guard v3.0.18 tag: inconsistent project metadata
- HOL Guard v3.0.18: Composer support matrix